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We examine the security of a protocol on cryptographic key distribution proposed by Yuen and 
Kim (1998 Phys. Lett. A 241 135). Theoretical and experimental analysis shows that, even if 
the eavesdropper could receive more photons than the legitimate receiver, secure key distribution is 
possible as long as the signal-to-noise-ratio of the eavesdropper does not exceed eight times (9 dB) 
that of the receiver. Secure key distribution was demonstrated using conventional fiber optics. The 
I secure key transmission rate in the experiment was estimated to be 2 Mb/s at its maximum (0.04 bit 

. per sender's bit.) The present protocol has advantages over other quantum key distribution protocols 

in that it is more efficient and more easily implemented, but careful design and management are 
, , , necessary to ensure the security of the cryptosystem. 
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I. INTRODUCTION 

> ■ . . 

, Cryptography is used to transmit a message from a sender (referred to as Alice) to a receiver (Bob) without leaking 

' useful information to others. It has been proved that a message can be transmitted securely if it is coded and 
' decoded by a sequence of random bits (key) whose length is equal to that of the message. The problem of secure 
transmission is then reduced to that of generating a secret key shared by Alice and Bob. Classical cryptosystems rely 
on computational complexity and may be broken by an effective algorithm or a powerful computer. Quantum key 
distribution (QKD) protocols, in contrast, provide an unconditionally secure key, the security of which is inherent in 
the laws of quantum mechanics. This remarkable advantage of QKD protocols has been attracting increasing research 
interest since the proposal by Bennett and Brassard Although QKD has been demonstrated in over-20- 

km-fiber communication channels [p|-p^, its application in practical communication systems is not straightforward. 
, The QKD protocols require single-photon transmission to guarantee the security, and thus are vulnerable to loss 
' and noise inherent in actual transmission channels. Optical amplifiers will not solve this problem, because the noise 
^ I of the optical amplifiers inevitably destroys the quantum correlation. Single-photon transmission requires the use 
of complicated and inefficient photon counting techniques instead of conventional analog detection, besides a truly 
'■ practical single-photon source is not yet available. The QKD protocols are therefore not fully compatible with the 
• i-H , current optical fiber communication systems. A secure key distribution protocol compatible with the current systems 
' is desirable. This would be a protocol that uses more than one photon and allows optical amplifiers to be used. Such 
^ a protocol would be based on coherent state photons, or classical light. 
■ - - ' Maurer [ pl has shown perfect cryptographic security can be obtained in a classical noisy channel with the help 
of a noiseless feedback channel. Yuen and Kim examined the principles underlying the QKD protocol with 
two non-orthogonal quantum states (B92 protocolfgj.) The security of the B92 protocol rehes on two facts [ p^ : 
(i) an eavesdropper (Eve) cannot accurately determine the value of each transmitted bit ( i.e., no efficient opaque 
eavesdropping.) (ii) Eve cannot closely correlate Bob's measurement results with her own ( i.e., no efficient translucent 
eavesdropping.) Yuen and Kim pointed out that these two conditions can be satisfied in a classical transmission 
system, where the detectors of Bob and Eve are under independent additive noise and show a small signal-to-noise- 
ratio (SNR.) They proposed a classical noise-based protocol for key distribution (referred here to as the YK protocol.) 
The YK protocol working with classical light, would have advantages in practical implementations. Proving the 
security in YK protocol is, however, subtler than in QKD protocols. Since many photons are transmitted to carry 
one-bit information, the conditions specified above will not be satisfied if the SNR of Eve's detection is sufhcicntly 
high. Eve's SNR can be increased by using low-noise detection equipment, or simply by moving closer to Alice than 
Bob (because of the fiber loss.) The original analysis of the security of YK protocol assumed the same SNR for Bob 
and Eve For practical implementations, it is important to determine the design rules of Eve's SNR and Bob's. 

In this article we quantitatively examine the security of the YK protocol, and show that the YK protocol is 
secure, even if Eve's SNR is 9 dB better than Bob's. We also show experimental results that demonstrate secure key 
distribution against translucent attack. Section 2 provides the condition for secure key distribution in terms of the 
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secure key distribution rate. Section 3 describes the experiment on the YK protocol using conventional fiber optics. 
Section 4 discusses the implementation issues. 



II. THEORY 



We first define the secure key distribution rate. Suppose Alice transmits an equally probable binary string to Bob. 
Shannon information between Alice and Bob is expressed by 



Iab = 1 + es log2 es + (1 - e^) log2 (1 - cb) 



(1) 



where es denotes the error rate of Bob's decision. Because of the decision errors, Bob has the information in only 
n-siftlAB of the Usift sifted bits. Alice and Bob exchange redundant information over the public channel in order 
to obtain the reconciled key. This procedure is called error correction, the best known practical protocol for which 
was given by Brassard and Salvail For successful error correction with Brassard-Salvail's protocol, the error rate 
should be less than 0.15. To establish a secret key, Alice and Bob use privacy amplification p^ , random hashing of 
the reconciled key into a shorter key. If they shorten the reconciled key of length Urec by the fraction r and sacrifice 
ns bits as a safety parameter, Eves's Shannon information on the final key of length rrirec — ns is bounded by 
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The fraction t is given by 



T= l + (l/n^ec) log Pc, 



(2) 



(3) 



where the collision probability Pc (AT) of X is defined as follows: Let A be a random variable with an alphabet X 
and distribution Px- The collision probability is the probability that X takes the same value twice in two indepen- 
dent experiments, that is, Pc (A) = J2xex i^)'^- The logarithm of the collision probability thus refers to Eve's 
information on the key. The collision probability can be expressed by the probability p{k) that k is the i-th signal of 
Bob's string and the joint probability pjk, I) that k is the i-th signal of Bob's string and I is the i-th signal of Eve's 
string. We have the following formula Mm for the fraction r: 
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According to Brufi and Liitkenhaus IT^], Bob can generate secure bits from his sifted bits at the rate R of 



R 



(1 - es) r - cb- 



(4) 



(5) 



We refer this rate R as the secure key distribution rate, and for secure key distribution its value be positive. The 
actual key generation rate is further reduced by multiplying the generation rate of the sifted key. In the following 
part of this section, we derive the conditions under which R is positive. 

In the YK protocol [Q, the bit values ("0" and "1") are encoded so as to make the probability distribution of the 
received signal symmetric. Alice sends encoded bits on a weak classical light. Signal so{t) = S(j){t) is transmitted for 
"0", and si{t) = —S(t){t) is transmitted for "1", where Jj,(l){t)dt = 1. We here measure the signal value as the voltage 
on the load resistance Rioad of a photodiode. Mean signal voltage S is defined by S"^ — Jrpsf{t)dt, and S^/Rioad 
represents the signal energy over the duration T (signal energy per bit.) The output r{t) of the detector contains 
the noise ri{t), so r{t) = Si{t) + n{t). If the noise is white Gaussian noise with spectral density cr^, the probability 
distribution of the detected signal V is expressed by 



PiV) 



(1/v^) exp 



1 / V 27r) exp 



- iV + S f/{2a^) 



{for "0") 
{for "1")' 



(6) 



where the signal is averaged over the duration T as ^ = Jj, r{t)dt. The SNR in this system is define by /? = S'/cr. 
In a conventional decision scheme the bit values are determined to be "0" if > and "1" ii V < 0. Decision errors 
will occur at the rate of Q {0), where Q is the scaled complementary error function defined by 
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Q{x) = ^ / exp (-2/V2) dy. (7) 

V ^TT Jx 

We set a threshold Vth = 7715 (m > 1) to make a decision: "0" if ^ > Vt/i and "1" if ^ < — Vt/i, but leave inconclusive 
if — Vt/i < 1^ < Vf/j. The probability of making a decision is given by the following decision rate: 

F+ = g((m+l)/3) + Q((m-l)/?), (8) 

and the error rate is 

_ g((m + l)/3) 



(9) 



The sifted key is generated from the raw bit string by the Bob's decision. The decision rate F+ thus refers to the 
generation rate of the sifted key. As seen in Eqs. (||) and (|^), the decision rate F+ and the error rate e are determined 
by the values of the SNR and the threshold. As described below, this error rate determines the joint probabilities 
p(fc, I) and therefore the secure key distribution rate. The system is thus fully characterized by the SNR and the 
threshold. The error rate can be reduced by increasing the threshold, but, a high threshold will also reduce the 
decision rate. Since, as we can see by comparing Fig. |^ and Fig. ^, the decision rate decrease faster than the error 
rate, the threshold value should not be set too high. 

As in the B92 protocol the inconclusive results play a essential role in guaranteeing the security of the key 
distribution. A finite threshold value of Bob enables him to make accurate decisions on his sifted key at a cost of the 
generation rate. Eve, on the other hand, should make a decision with zero threshold in order to obtain conclusive 
results for all the transmitted bits. If Eve uses a finite threshold in her decision, she will obtain the inconclusive 
results on the sifted bits. The assumption of independent noise prevents Eve from predicting which bit Bob will 
obtain a conclusive result. Eve can acquire no information from these inconclusive bits. Since Eve's error rate is 
less than 1/2, she will obtain more information by making a decision with zero threshold. Therefore, Bob can make 
more accurate decisions on the sifted key bits than Eve can. That is. Bob has more information than Eve, and can 
distill secure key bits with Alice. 

Now we will examine the conditions for security against eavesdropping. We here consider only two simple kind of 
eavesdropping, translucent attack and opaque attack. A translucent attack can be made by simply putting a beam 
splitter in the transmission channel. The translucent attack to the YK protocol, in contrast to those to the QKD 
protocols, will not change the state of the transmitted light. The probability distribution of Bob's bits is the same as 
that of Alice's, p(0) — p{l) — 1/2, because after error correction Alice and Bob share completely correlated results. 
The joint probabilities p{k,l) are p(0,0) = p(l, 1) = (1 — e£;)/2 and p(0, 1) = p(l,0) = 6^/2. The fraction t is 
calculated from Eq. as 

r = 1 + log2 (1 - 2eE + 2e|) . (10) 

The secure key distribution rate can be estimated by using Eqs. (|l|), (||), and ([lO|). Figure || shows Eve's required 
error rate as a function of Bob's. As Bob's error rate cb increases, Eve's error rate should be increased in order to 
obtain a positive secure key distribution rate . For example, if Bob's error rate is 0.15, Eve should make errors at a 
rate greater than 0.27. This implies that SNR of Eve's system should be less than 0.38 for white Gaussian noise. On 
the other hand, Bob's SNR should be better than 0.057 to keep his error rate smaller than 0.15 and his decision rate 
at 10~^. The secure key distribution is therefore possible even if Eve's SNR is six times (8 dB) as large as Bob's. The 
tolerance of the SNR increases as Bob's error rate decreases, and it reaches 10 dB for cb — 0.01. 

In an opaque attack. Eve receives all the photons in rjn out of the n bits sent by Alice. Then Eve sends the rjn bits 
to Bob according to her decision. Eve never touches the rest of the bits ((1 — ry) n bits) and forwards them to Bob. To 
protect information from opaque attack. Bob should determine his threshold according to the average signal intensity 
of each bit. If he observes only the average intensity over many bits. Eve can set a finite decision threshold to reduce 
her error rate and will then obtain conclusive results for "fijn bits (7 < 1.) If she sends only the conclusive results 
with signals 7"^ times as intense as received. Bob will obtain the same long-time average signal intensity he would 
if Eve did not intercept the photons. If Bob observes the signal intensity of each bit. Eve must send every bit with 
the same intensity as she receives it. Eve then should make a decision with zero threshold, otherwise she will lose the 
information on the inconclusive results. There is a trade-off for Eve on the fraction 77: a large rj will increase Eve's 
information gain, but will also make her easily detectable from the increase of Bob's error rate. Bob's error rate on 
the unintercepted bits is cb, but the error rate on the intercepted bits is {1 — ce) gb + esi^ — sb)- The eavesdropping 
thus increases Bob's error rate to 

c'b = (l- v) +11 [(1 - e_E) cb+ce (1 - Cb)] ■ (11) 
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To calculate the secure key distribution rate by using Eqs. (|l]), (||), and (10), we estimate the joint probabilities p (k.l) . 
After the error correction, Bob has (1 — e'g)nF^ bits. The probability distribution i symmetric: p{0) = p{l) = 1/2. 
Eve obtains (1 — e^) (1 — es) r/n_F+ +(1/2)(1 — r/)(l — eB)nF+ correct results and e_BeB7?nF+ + (l/2)(l — ?7)(1 — e_B)'^-F+ 
incorrect results on Bob's bits. The joint probabilities are obtained as 



[(1 - es) (1 - gb) 7? + (1 - eB)(l ~ v)/2] nF+ 
2(l-e4)nF+ 

_ [(l-eE)v+{l-v)/2]{l-eB) 

n n^ - eEeBVnF+ + (1 - ej3)(l ~ r])nF+/2 
2(l-e'^)nF+ 
^ eBeg?7 + (l/2) (1 - eg) (1 - r/) 

2(1-6'^) 

p(0,0) =p(l,l) 
p(0,l) =p(l,0). 

Figure ^ shows the minimum required values of Eve's error rate for secure key distribution (i? > 0) as a function of 
Bob's error rate e^. Though Bob can observe only e'g values, he can estimate es from the SNR of his detection 
system. Eve will be detected if e'^ ^ e^. The detection is easy if Bob's error rate is much lower than Eve's. A high 
error rate for Bob may hide Eve, but secure key distribution is possible even in this case. Suppose es — 0.1 and 
e'g = 0.15. As shown in Fig. |[ the secure key distribution rate is positive if Eve's error rate is larger than 0.12. 
If the system is under white Gaussian noise, this condition on the error rate is satisfied when Eve's SNR is smaller 
than 1.35 (1.3 dB.) Since Bob's SNR should be better than 0.089 (-10.5 dB) to keep the decision rate at 10"^ and 
bb = 0.1, the tolerance in SNR is 11.8 dB. This small SNR for Eve implies that the signal should be sent on a weak 
light. Increasing the light intensity reduces Eve's error rate, and makes the secure key distribution impossible. 



III. EXPERIMENT 



In implementing the YK protocol, we should code the bit values in such a way that the probability distribution of 
the received signals is symmetric . In this experiment we used the unipolar Manchester code. This code represents " 1" 
as a change from ON to OFF and "0" as a change from OFF to ON. It can be decoded as follows: divide the incident 
light into two paths, one of which is set one half of the pulse width longer than the other. Then take a difference 
of the two light intensities by a balanced detector. The latter half of the pulse slot yields a negative signal for " 1" 
and a positive signal for "0". Binary phase shift keying (BPSK) also yields a symmetric distribution by homodyne 
detection, and would be more sensitive, but unipolar Manchester code is easier to implement. 

Figure H shows the experimental setup. Two distributed feedback (DFB) laser diodes (LDs) served as 1.3 fiui light 
sources. A pattern generator provided a signal pulse string to modulate one DFB LD (signal LD) directly. The second 
pattern generator was synchronized to the first, and provided an 8-ns pulse at the beginning of each pulse string. 
This pulse modulated the other DFB LD (trigger LD) directly to generate a trigger light pulse. The output of the 
signal LD was set weaker than that of the trigger LD. The clock frequency in the present experiment was 25 MHz. 
Only a fixed pattern of 101010- • • was transmitted. The coded signal light then became a square wave with a duty of 
50 % and a pulse duration of 20 ns. We sent strings of 30.8 kbits. The outputs of the two LDs were combined and 
attenuated by an attenuator (ATTl.) To simulate the translucent attack by an eavesdropper, we inserted a 50:50 
divider. An attenuator (ATT2) was placed in one arm of the divider to examine the SNR tolerance for the secure key 
distribution. The signals of both outputs were detected by the receivers. Each receiver consisted of a 50:50 divider, a 
fiber delay of a half pulse width, and a balanced detector. The balanced detectors made of two commercial InGaAs 
pin photodiodes loaded by 50 ft resisters were operated in analog mode. The catalog data (typical values) for the 
quantum efficiency and the dark current of the photodiodes at 25 C were 90 % and 5 nA. The photodiodes ware not 
cooled. The output signals of the receivers were led to amplifiers (G — 40 dB) and then to analog-digital converters. 

Figure ^ shows a typical probability distribution of the output signal from the amplifier. It is well represented by 
the sum of two Gaussians. The intensity of the optical signal was 0.380 /iW (-34.2 dBm) at the input port of the 
receiver, and the SNR of this signal was 1.0 (0 dB.) We averaged the output pulse over the duration (10 ns), and 
evaluated the decision rate and error rate as a function of the SNR and the threshold. The results are shown in Fig. 
^ and Fig. ^. The experimental results agree well with the theory assuming white Gaussian noise. These indicated 
that white Gaussian noise dominated the present receiver sensitivity, and that the security analysis described in Sec. 
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2 can be applied to the experiment. The number of the sifted bits became small when the threshold value is high. 
We had less than 30 bits, if the decision rate is less than 10^'^. This insufficient sample number caused the error rate 
fluctuation observed for large m's in Fig. ||. For SNR values up to dB, the noise level was almost same as the dark 
noise level, but for larger SNR, it increased with the signal intensity. Dark current of the photodiodes was negligible 
compared to the thermal noise. These indicates that, for SNR values up to dB, the sensitivity of the system was 
dominated by thermal noise, which is constant to the input photon number. As the intensity increased, the thermal 
noise was exceeded by shot noise, which is proportional to the input photon number. SNR was proportional to the 
square of the input power for weak signals, and tended to be proportional to the input power as the signal intensity 
increased. 

The error rate shown in Fig. ^ provides a criterion for key distribution secure against opaque attack. A low error 
rate of 0.038 was obtained for weak signals by setting the threshold at to = 10, where the SNR was -9.25 dB. The 
decisions were made at the rate of 0.0008, slightly lower than 10"'^. This error rate was lower than the theoretical 
value of 0.072 because of the fluctuation described above. Using es = Hue in Fig. ^, we conclude that the key 
distribution is secure if Eve's error rate is larger than 0.1, where we use the theoretical value of the error rate (0.072) 
for Bob. This condition is satisfied if Eve's SNR is dB, because we obtained the error rate of 0.15 in the experiment. 
Bob's advantage in SNR was thus greater than 9.25 dB. This advantage was almost constant for large SNR signals. 

Security against the translucent attack was examined as follows. We assigned one receiver that followed ATT2 as 
Bob, and the other receiver as Eve. ATTl affected the SNRs of both Bob and Eve, whereas ATT2 determined the 
ratio of the SNRs. The decisions in Bob were recorded with several values of the threshold to, while the Eve's decisions 
were recorded with the threshold fixed at zero. We measured the error rate cb and decision rate of Bob and the 
error rate of Eve. We estimated the joint probabilities p(0, 0), p(0, 1), p(l, 0), and p(l, 1) from the bit data about 
which Bob made correct decisions. Finally, we calculated the secure key distribution rate R by using Eqs. (|^), (|^), 
and (|). Figure H shows the secure key distribution rate as a function of the error rates of Eve and Bob. The symbols 
in Fig. ^ show the secure key distribution rates estimated from the experiment. Experimental results agree well with 
theoretical results (lines.) The secure key distribution was achieved if error rates of Eve and Bob are in the region 
above the i? = line in Fig. |[ The decrease in Bob's SNR reduced the range of the signal intensity for secure key 
distribution. Secure key distribution was impossible when Bob's SNR was -9 dB smaller than that of Eve. This result 
also agrees well with the prediction. We obtained the largest actual secure key distribution rate F+R — 0.04 when the 
SNRs of both Bob and Eve were unity (0 dB) and Bob's threshold was set to m = 2. The observed error rates were 
0.01 for Bob and 0.15 for Eve. The secure key distribution rate was R = 0.29. Higher secure key distribution rates 
were obtained by setting larger threshold values, but the reduction in the decision rate decreased the product F+R. 
Alice transmitted signals at 50 Mb/s, so that the key transmission rate in the present experiment was 2 Mb/s. This is 
a hundred times as fast as the key transmission rate reported in the QKD experiments . The transmission rate 
was limited only by the electric circuits. The secure key would be transmitted at 400 Mb/s if a 10-Gb/s transmission 
channel were used. 



IV. DISCUSSIONS 



This theoretical analysis has shown that the secure key distribution is possible as long as the ratio of Bob's SNR 
to Eve's is better than -9 dB, and the experimental results presented here confirmed it. A practical cryptosystem 
should thus be designed to satisfy this condition. Eve may stay much closer to Alice than Bob, and her signal may 
be larger than Bob's because of the fiber loss. We estimate a limit of the transmission distance in the following. It 
would be very difficult to use complicated networks, where the path of a traffic is not fixed. We have to construct a 
cryptosystem on a simple network or a point-point channel. Suppose, for simplicity, we construct it on a point-to-point 
channel. SNR is proportional to the square of the light intensity when the system sensitivity is limited by thermal 
noise. Then Bob's advantage of 9 dB refers to the fiber length of 22.5 km using a lowest loss fiber (0.2 dB/km) and 
neglecting connection loss. SNR is proportional to the light intensity in systems limited by shot noise, and the fiber 
can be as long as 45 km in those systems. This values would be increased assuming the translucent attack, because 
Eve would tap the channel and receive small part of the signal. 

Amplifiers can be used in YK protocol as long as the SNR permits. They will improve the SNR by reducing the 
effect of the thermal noise, and therefore will be useful when the system is limited by the thermal noise. In the shot 
noise limit, even an ideal amplifier reduces the SNR by 3 dB. The use of amplifiers is restricted by this degradation 
in the SNR. At most three amplifiers are thus possible. 

The above estimation assumed that Bob and Eve use the same detectors. Bob should reduce system noise as possible 
to guarantee the security, by cooling the receiver, for example. If he can suppress all the thermal noise, the SNR of his 
system will be limited by shot noise, the standard quantum limit pq|. The mean photon number transmitted in this 
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system should be reduced to unity, because the SNR of dB refers to mean photon number of unity in the shot noise 
hmited systems. The error rate can be reduced below the standard quantum limit by optimum decision |l9| , ^0t] . The 
improvement will be apparent for small mean photon numbers. Security analysis based on quantum detection theory 
as well as practical implementation of the optimum decision are open for further study. It would be noteworthy that 
the security analysis described in the present article will provide a security criteria for the B92 protocols employing 
dim coherent lights. 

The YK protocol provides more efficient key distribution at higher bit rates than do other QKD protocols, but 
it requires that the signal intensity be controlled to keep Eve's SNR advantage smaller than 9 dB. This may be a 
disadvantage compared to the QKD protocols like BB84, where the unconditional security is proved if the photons 
are generated by a perfect single photon source |2l|,^. However, it has been shown that the Eve's advantage in 
SNR will limit the efficiency of the protocol in a lossy channel. The SNR control would be also required in actual 
BB84 systems. 



V. CONCLUSION 



Quantitative analysis of the security of the Yuen-Kim protocol shows that the secure key distribution is possible 
even if the eavesdropper receives signals with a signal-to-noise-ratio better than that with which the legitimate receiver 
receives them. It has been shown that the signal-to-noise-ratio of the legitimate receiver may be -9 dB smaller than 
that of the eavesdropper. The results of an experiment using conventional fiber optics agrees well with the analysis 
results. These results have demonstrated a practical implementation of a secure key distribution protected by the 
laws of physics. We think the YK protocol would be a solution for practical cryptography systems. 
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FIG. 1. Relation between threshold and the decision rate obtained at various signal-to-noise-ratios: diamonds 7.8 dB, squares 
2.65 dB, triangles -3.28 dB, crosses -9.25 dB, stars -15.1 dB, and circles -21.4 dB. Lines were calculated assuming white Gaussian 
noise. Symbols show values obtained in the experiment. 
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FIG. 2. Relation between threshold and the error rate obtained at various signal-to-noise-ratios. The meanings of the symbols 
are the same as in Fig. 1. 

FIG. 3. The requirement for Eve's error rate as a function of Bob's error rate to achieve secure key distribution against 
translucent attack. Lines are calculated for the values of the secure key distribution rate R = 0, 0.1, 0.2, and 0.4. Symbols 
represent the secure key distribution rate obtained in the experiment. Crosses denote R <0, diamonds: < i? < 0.1, triangles: 
O.K R< 0.2, squares: 0.1 < R < 0.2 and circles: R > 0.4. 

FIG. 4. The requirement for Eve's error rate as a function of Bob's error rate to achieve secure key distribution against 
opaque attack. Lines are calculated for the values of the Bob's error rate without eavesdropping. 

FIG. 5. Experimental set up for demonstration of the Yuen-Kim protocol. In Alice's transmitter, pattern generators (PG) 
drive two lasers. ATT., ATTl and ATT2 are attenuators. In the receivers of Bob and Eve, the light in one of the divided path 
is delayed. Lights are detected by balanced detectors made of two photodiodes. ADC: analog-digital converters. PC: personal 
computer. 

FIG. 6. A typical probability distribution of the output signal from the amplifier. Diamonds denote experimental result, 
broken lines show the Gaussians used for fitting, and the solid line shows the sum of those two Gaussians. 
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Fig. 1 of "Security of classical noise-based cryptography" by Tomita and Hirota 
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Fig.2 of "Security of classical noise-based cryptography" by Tomita and Hirota 




Fig.3 of "Security of classical noise-based cryptography" by Tomita and Hirota 




Fig.4 of "Security of classical noise-based cryptography" by Tomita and Hirota 




Fig.5 of "Security of classical noise-based cryptography" by Tomita and Hirota 
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Fig.6 of "Security of classical noise-based cryptography" by Tomita and Hirota 



